Overview
आरंभ Tours & Travels is committed to maintaining the security of our platform and protecting our customers' data. Security researchers play a vital role in identifying vulnerabilities we may have missed.
If you have discovered a security vulnerability in any आरंभ system, we encourage you to disclose it to us responsibly before making it public. We are grateful for responsible security research.
How to Report a Vulnerability
Please submit your vulnerability report via email:
Please include in your report:
- Description of the vulnerability and its potential impact
- Step-by-step reproduction steps (proof-of-concept code or screenshots)
- Affected URL(s), parameters, or API endpoint(s)
- Your name/handle and contact email for follow-up (optional but appreciated)
In Scope
The following आरंभ properties are in scope for responsible disclosure:
- aarambhatravels.in — Main customer website
- admin.aarambhatravels.in — CRM admin portal
- api.aarambhatravels.in — Backend REST API
Priority issues we want to hear about:
- Authentication bypass or privilege escalation
- Insecure Direct Object Reference (IDOR) allowing access to other users' data
- SQL injection or NoSQL injection
- Cross-Site Scripting (XSS) with meaningful impact
- Cross-Site Request Forgery (CSRF)
- Sensitive data exposure (API keys, customer PII)
- Payment flow vulnerabilities
- Server-Side Request Forgery (SSRF)
Out of Scope
The following are generally not eligible for our disclosure programme:
- Volumetric Denial of Service (DoS/DDoS) attacks
- Social engineering attacks against our staff
- Physical security attacks
- Vulnerabilities in third-party software we use (report directly to that vendor)
- Self-XSS that requires the victim to take deliberate unusual action
- Missing security headers without a demonstrated exploit
- SSL/TLS version or cipher suite issues without proven attack
- Username/email enumeration via timing (we have fixed this; please verify first)
- Clickjacking on pages with no sensitive actions
Our Response Commitment
Safe Harbor
We consider security research and disclosure conducted in accordance with this policy to be authorised activity. आरंभ Tours & Travels will not initiate or recommend legal action against researchers who:
- Report vulnerabilities to us before public disclosure
- Act in good faith and avoid violating privacy, causing service disruption, or destroying data
- Do not access or download more data than is strictly necessary to demonstrate the vulnerability
- Stop testing immediately upon discovering customer personal data and report it to us
If you have any questions about whether your planned research is in scope, email security@aarambhatravels.in before proceeding.
